Two conditions must be met for a measure to be displayed for mitigation within a risk:
The protection objective of the measure and the risk must match
The organisational units of the measure and the risk must match.
Example 1 - Not selectable
Measures: Removal of the USB drives on all PCs
Organisational units : Caratraining
Further organisational units: ALL units
Protection objective: Integrity
Risk: Fire in the server room
Affected organisational units: Caratraining
Other organisational units: ALL units
Warranty target: Availability
Result:
Organisational units match
Warranty targets do NOT match.
The measure cannot be selected for this risk.
Example 2 - Selectable
Measure: Maintenance of fire protection equipment
Affected organisational units: Caratraining
Other organisational units: Caratraining > Cara GmbH > Operations > Operations Team
Protection objective: Availability
Risk: Fire in the server room
Organisational units: Caratraining
Further organisational units: ALL units
Protection objective: Availability
Result:
Organisational units match.
Warranty targets match.
The measure can be selected for this risk.